CVE-2025-11145

7.5

CBK Soft Software · enVision

The CBK Soft Software enVision platform contains an observable discrepancy vulnerability that allows for account footprinting and the unauthorized exposure of sensitive personal information.

Executive summary

An unauthenticated vulnerability in the CBK Soft Software enVision platform allows for account footprinting and the exposure of sensitive user data, posing a significant risk to information confidentiality.

Vulnerability

This vulnerability involves an observable discrepancy (CWE-203) that facilitates account footprinting, allowing an unauthenticated remote attacker to harvest sensitive or private personal information.

Business impact

The exposure of sensitive personal information can lead to severe privacy violations, potential regulatory non-compliance, and an increased risk of targeted social engineering or identity theft attacks against users. Given the CVSS score of 7.5, this high-severity flaw represents a significant risk to organizational data integrity and user trust.

Remediation

Immediate Action: Organizations should upgrade to enVision version 250566 or higher immediately to address the underlying logic discrepancy.

Proactive Monitoring: Security teams should monitor system access logs for unusual patterns of sequential account queries or mass enumeration attempts originating from single IP addresses.

Compensating Controls: Deploy a Web Application Firewall (WAF) to detect and block traffic patterns indicative of account enumeration or automated scraping of user identifiers.

Exploitation status

Public Exploit Available: No (exploit_available: false).

Analyst recommendation

The ability for an unauthenticated actor to perform account footprinting is a critical security failure that necessitates prompt remediation. Administrators must prioritize updating the enVision software to the patched release and verify that monitoring controls are in place to detect any attempts to leverage this information disclosure flaw.

Sources

Originally found and disclosed by Emre AKTAŞ, per the CVE Program record.